Get more replies from employers
Send a job-specific resume in minutes.
Skillmine Technology seeks a hands-on Offensive Security leader to build and run adversarial testing across traditional and AI systems. You will direct a small team, drive high‑complexity red team engagements, and translate findings into concrete risk reductions for the business.
Responsibilities cover full-scope red team operations, AppSec reviews, social engineering, and AI/LLM security testing, with clear, actionable reporting for engineers and executives.
We are seeking a hands-on Offensive Security leader to build and run adversarial testing across both our traditional attack surface and our AI systems. You will operate as a senior offensive practitioner and a team lead:personally,driving high-complexity red team engagements while directing a small team, setting methodology, and translating findings into concrete risk reduction for the business.
Plan and leadfull-scope red team operations against networks, web/mobile applications, cloud environments, APIs, and identity systems, emulating real-world adversary TTPs and aligning to OWASP, OSSTMM, and MITRE ATT&CK.
Execute end-to-end attack chains — initial access, privilege escalation, lateral movement, persistence, and exfiltration —with modern C2 frameworks, developing custom tooling and payloads, and safely exercising detection and response capabilities alongside the blue team (purple teaming).
Performapplication security (AppSec) reviews, secure code review, penetration testing, and analysis and triage of bug bounty submissions to validate and prioritize real-world risk.
Conductsocial engineering, phishing, and physical/assumed-breach scenarios where scoped and authorized.
Produceclear, prioritized findings with reproducible proof-of-concept, threat models, deep-dive reports, and pragmatic remediation plans for technical and executive audiences.
Design and run adversarial testing ofLLM-powered products and agents for prompt injection (direct and indirect), jailbreaks, sensitive data exposure, insecure tool/function-calling and plugin usage, training-data extraction, and unsafe autonomousbehavior.
AttackAI systems across multiple integration and attack surfaces — API, token-based,cURL, and headless-browser methods — and red-team MCP (Model Context Protocol) architectures, AI gateways, and native and third-party guardrails.
Develop novelattack techniques against models and the surrounding application stack (RAG pipelines, agent frameworks, guardrails, model gateways), referencing frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI RMF.
Buildevaluation harnesses and automated red-teaming pipelines to measure model robustness, jailbreak resistance, and guardrail efficacy at scale.
Partnerwith ML and product teams on mitigations — system-prompt hardening, input/output filtering, guardrail tuning, and safety fine-tuning — and re-test to prove effectiveness.
Experience:10+ years in offensive security / red teaming, with a track record of leading complex, full-scope engagements.
Offensive depth:deep, demonstrable expertise across network, web/app, cloud (AWS/Azure/GCP), and identity attacks, plus custom exploit and tooling development (Python, Go, or C/C++).
AI security:hands-on experience attacking or securing LLM-based systems (prompt injection, jailbreaks, agent/tool abuse), Agentic AI architectures, MCP and AI-gateway security, and adversarial ML techniques, with a solid grasp of ML fundamentals.
Model fluency:practical experience training, fine-tuning, or heavily operationalizing LLMs, and using frontier models to automate real work.
Offensive AI use:proven, hands-on experience using LLMs to create offensive testing — building attack payloads, exploits, phishing content, red-team tooling, and automated test cases with model assistance.
Leadership:able to communicate risk clearly to engineers and executives, and to lead and mentor others.